Glow Cloud Security

Terms & policies

The plain-English terms for engaging a Glow Cloud M365 Security Assessment. Nothing surprising - read-only, fixed-scope, a report you own.

The engagement

When you engage a Glow Cloud M365 Security Assessment - or one of its options (the Sharing & Permission Deep-Dive, the Full Suite, or the Permission (RBAC) Map) - you are engaging a fixed-scope, point-in-time, read-only assessment of your Microsoft 365 tenant, scored against the Glow Cloud M365 Security Framework and delivered as a self-contained, interactive report you own and keep. It is not a certification or an accredited audit, and it is not legal advice. Assessments are aligned with recognised industry best practice.

How access works

We only ever read. We never write to your tenant, change a setting, or install anything. Access is least-privilege and revocable at any time, and every read shows in your own Microsoft 365 audit log.

What access does it need? +

One read-only approval covers most of the assessment - identity, email, storage, Purview, Intune, licensing and more. Two minutes, needs a Global Administrator.

Two further approvals are set up together on your onboarding call:

  • Fabric / Power BI checks - a read-only admin-API setting in your Fabric portal (plus adding our read-only connection to a security group you control).
  • The permission map - approving a second read-only connection, plus a dedicated SharePoint Administrator account you create for the engagement and disable when we hand over. Microsoft shows a site’s own permission list, and some tenant-level SharePoint settings, only to a signed-in administrator, so a full run signs in at up to three points: twice early on and once near the end. We sign in ourselves, so none of your people need to be on hand at both ends of an overnight run. SharePoint Administrator is a privileged role rather than a read-only one, so the account stays yours to audit and revoke, and we commit to using it for reads only. This one is not truly optional if you have bought the map: reading each site’s own permission list is what produces the library-level detail. Decline it and the map still renders, but it shows access rolled up to the site.

Skip the Fabric setting and the assessment still runs, with those checks clearly marked "requires consent" in your report, never silently missing and never guessed. Skip the SharePoint account and the map is shallower rather than absent, and we will say so at the readout. Nothing is scored against you for access you chose not to grant. And the price is the price: full coverage costs nothing extra - the only thing gating your report is what you choose to grant.

Booking, invoicing & pricing

Assessments are professional services, booked rather than bought at a checkout. You tell us which report you need, we confirm the scope, and Glow Cloud Solutions invoices you directly - payment is by the method and terms stated on the invoice. Prices on this site are in GBP and no VAT is currently charged. One price per product - no size-based or feature-based variants; any bundled add-ons (for example the Permission Map added to a Deep-Dive or Full Suite) are agreed when we confirm the scope and appear on the same invoice.

Onboarding & delivery

After booking you have a short onboarding session, where we set up read-only access together (or ahead of time if you prefer). We then run the assessment and hand you the report within the delivery window for your product. The report arrives as a single encrypted file, via a secure link bound to your named recipient, and unlocks in your browser with a passphrase we relay separately - no agent to install, nothing that lives in someone else's dashboard, and the decryption happens entirely on your machine. From delivery, the report and its passphrase are in your care: the file is yours to own and keep. Retainer clients also get an optional portal login showing their headline score, trend and delivery status; it never holds your findings, your report or your passphrase.

Refunds, delivery & your data

The fine print, plainly

  • Fixed-scope engagement - full refund if we can't gain read-only access within 5 business days; non-refundable once the assessment run begins.
  • Delivery - 3 business days from access for the Assessment; 5 business days for the Sharing & Permission Deep-Dive, Full Suite and RBAC Map.
  • Your data - the working data stays on our own secured machine, never in a portal you sign in to. We sweep delivered copies on a regular cycle and delete everything for a client on request, in writing, at any time. A retainer keeps prior runs by design, because the improvement measure is computed from them.
  • Custody on delivery - the report arrives as a single encrypted file via a link bound to your named recipient, with the passphrase relayed separately; from delivery, both are in your care - keep them apart.

Contact

The Glow Cloud M365 Security Assessment is a service of Glow Cloud Solutions. Questions about these terms: hello@glowcloud.uk. See also our privacy & cookies policy.